New AI Vulnerability: Agentjacking Exposed
A recent attack exploited a flaw in Sentry, allowing unauthorized code execution in AI systems like Claude Code. Discover how this vulnerability could affect your organization and what steps to take now.

Understanding Agentjacking Vulnerability
A new security disclosure by Tenet Security has revealed a critical vulnerability known as agentjacking, which affects AI coding agents connected to platforms like Sentry, Datadog, and Jira. This flaw allows attackers to execute malicious code under the guise of legitimate error reports, leveraging the developer's privileges without triggering any alerts.
The research identified over 2,388 organizations with publicly exposed Sentry credentials, making them susceptible to this type of attack. The implications are severe, as the attack can occur without breaching any security policies or stealing credentials. Instead, the attacker sends a valid API call, and the system unwittingly executes the malicious instructions.
- Key points to consider:
- 85% success rate in controlled tests.
- No alerts triggered during the attack.
- Organizations must audit their Sentry configurations immediately.